CVE-2024-36354CWE-1231

Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a system with a…

High · published September 6, 2025

CVSS v3.1
7.5
EPSS
0%
Percentile
5.8
In the wild
Unconfirmed
What it is

Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a system with a non-compliant DIMM, or control over the Root of Trust for BIOS update, to bypass SMM isolation potentially resulting in arbitrary code execution at the SMM level.

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00163 · 5.8th percentile
Weakness
CWE-1231 · Improper Prevention of Lock Bit Modification
Published
2025-09-06T18:06Z
EPSS history
Timeline
  • 06 SEP 18:06Z
    Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a system with a…
    cvelistv5